Chartkick is a charting library for web applications available across multiple platforms (Chartkick and Chartkick.js), whose vulnerability exposure centers on client-side input handling and output rendering. The observed weakness classes—cross-site scripting and injection flaws in downstream web page generation—reflect the inherent risks of a component that processes and renders user-controlled data in browser contexts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chartkick Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18841HIGH Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution. | Nov 11, 2019 | 7.3 | 23 | NO | NO |
CVE-2019-12732MEDIUM The Chartkick gem through 3.1.0 for Ruby allows XSS. | Jun 6, 2019 | 4.7 | 19 | NO | NO |
CVE-2020-16254MEDIUM The Chartkick gem through 3.3.2 for Ruby allows Cascading Style Sheets (CSS) Injection (without attribute). | Aug 5, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chartkick Project.
Media articles that mention a CVE ID that affects a product developed by Chartkick Project — matched by CVE ID, not by vendor name.